Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits

2026-07-19T08:51:42Z3f4af3a9b9a12fd1c8cb312579c9ff2b902d788c0d783d1ecc5cfe1e2af23756
CISADaxinEYErnst & YoungFortiSandboxFortinetHollowByteKNXKnown Exploited VulnerabilitiesMicrosoft SharePointNichireiOpenSSLOracleScattered SpiderStarland RATStupigTuxBot v3','IoT botnet','AI-generated malware','DoS','RCEUAT-11795WLDRWordPressdata breachrootkitsupply-chainthird-partywp2shell

What happened

Multiple high-impact security events and disclosures: public exploits released for two critical WordPress “wp2shell” flaws (CVE-2026-63030, CVE-2026-60137) that can be chained for pre-auth remote code execution; Okta/Red Team disclosed an OpenSSL memory-exhaustion DoS named “HollowByte”; Symantec found the long-running China-linked Daxin kernel rootkit and a new Stupig backdoor on a manufacturer’s network; U.S. CISA added multiple flaws (including CVE-2023-4346) to its Known Exploited Vulnerabilities catalog (Fortinet FortiSandbox, Microsoft SharePoint, KNX, Oracle); Ernst & Young reported a 3

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
3f4af3a9b9a12fd1c8cb312579c9ff2b902d788c0d783d1ecc5cfe1e2af23756
Enrichment time
2026-07-19T08:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits · Baitaphish